APP-03.2: Security testing in the pipelines should include SAST (static analysis) and SCA, which are the two primary categories of tooling to detect application-level security defects. At least some pipelines should use these tests, but for Level 3, this does not need to be consistent or standardized yet.
  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none